[ 
https://issues.apache.org/jira/browse/KNOX-3491?focusedWorklogId=1044547&page=com.atlassian.jira.plugin.system.issuetabpanels:worklog-tabpanel#worklog-1044547
 ]

ASF GitHub Bot logged work on KNOX-3491:
----------------------------------------

                Author: ASF GitHub Bot
            Created on: 29/Sep/26 09:55
            Start Date: 29/Sep/26 09:55
    Worklog Time Spent: 10m 
      Work Description: github-actions[bot] commented on PR #1432:
URL: https://github.com/apache/knox/pull/1432#issuecomment-5887869083

   ## Test Results
     4 files    4 suites   42s ⏱️
   127 tests 127 ✅ 0 💤 0 ❌
   145 runs  145 ✅ 0 💤 0 ❌
   
   Results for commit 29d4de48.
   
   
[test-results]:data:application/gzip;base64,H4sIAPuKu2oC/13MSw7CIBSF4a00jB1QCqW4GcMzubEthsfIuHcpqYgOv/8k54kcrDai60AvA4oZUoPJQSbw+0FSXJZ0bCPhH91i1vo/3eFREm7BSVh/gg3Bh7OEvNdPyk60y658H6u7w+r+T/ttg1SAiDDUWLpwbA3jQhuHzaQmoeZpXvSoiVRMcWbR6w1dDOJ4BAEAAA==
   




Issue Time Tracking
-------------------

    Worklog Id:     (was: 1044547)
    Time Spent: 40m  (was: 0.5h)

> Allow JWT aud validation against request header values and include an initial 
> delegation token only validator
> -------------------------------------------------------------------------------------------------------------
>
>                 Key: KNOX-3491
>                 URL: https://issues.apache.org/jira/browse/KNOX-3491
>             Project: Apache Knox
>          Issue Type: Sub-task
>          Components: JWT
>            Reporter: Harrison Sheinblatt
>            Priority: Major
>          Time Spent: 40m
>  Remaining Estimate: 0h
>
> Extend JWT aud claim validation to allow for custom validators that require 
> the request parameter so they can validate against the destination from 
> headers. Retain the existing default that validates aud claims against a 
> fixed, configured allow list.
> Add a validator implementation that can validate delegation JWTs, those with 
> an act claim, for kubernetes environments. aud claim values in such tokens 
> were already authorized via delegation policy which can include allowed 
> audience lists. This validation restricts those tokens so that they can be 
> used only for k8s destinations that match. Provide flexibility in the headers 
> used and enable partial matching of the aud claim so that parts of the 
> destination can be used to validate the aud claim. This allows one to 
> validate what can be validated in more different k8s configurations, even if 
> all the destination information is not available via trusted headers.



--
This message was sent by Atlassian Jira
(v8.20.10#820010)

Reply via email to